<!doctype html>
<html>
    <head>
        <script src="../dist/purify.js"></script>
    </head>
    <body>
        <!-- Our DIV to receive content -->
        <div id="sanitized"></div>

        <!-- Now let's sanitize that content -->
        <script>
            /* jshint globalstrict:true, multistr:true */
            /* global DOMPurify */
            'use strict';

            // Specify dirty HTML
            var dirty = '<p>HELLO</p><style>*{x:expression(alert(1))}</style>\
                <iframe/\/src=JavScript:alert&lpar;1)></ifrAMe><br>goodbye</p><h1>not me!</h1>';

            // Specify a configuration directive, only <P> elements allowed
            // Note: We want to also keep <p>'s text content, so we add #text too
            var config = { ALLOWED_TAGS: ['p', '#text'], KEEP_CONTENT: false };

            // Clean HTML string and write into our DIV
            var clean = DOMPurify.sanitize(dirty, config);
            document.getElementById('sanitized').innerHTML = clean;
        </script>
    </body>
</html>
